Тип публикации: Proceedings Article
Дата публикации: 2023-07-14
Краткое описание
With the growing adoption of DevOps and the rise of containerization and Continuous Integration/ Continuous Deployment (CI/CD) in software development life cycle (SDLC) has brought significant changes to the industry. While these methods offer many advantages, they also present unique security challenges, as containerized applications are more susceptible to cyber attacks than traditional deployments, security has become a significant concern. Security scanning is an essential aspect of DevSecOps pipelines, involving the analysis of software images deployed to cloud environments to identify vulnerabilities and mitigate security threats. This study will involve a thorough review of existing literature on containerization and CI/CD security and will analyze current security practices and measures used in containerization-based CI/CD systems. Various tools and techniques have been proposed for implementing and automating image security scanning in DevSecOps pipelines by integrating DAST (Dynamic application security testing) and SAST (Static application security testing) vulnerability scanning.. This research proposes a method for implementing and automating image security scanning using the Snyk and StackHawk tool, which provides a dashboard for SAST and DAST separately for monitoring scanning results and automating vulnerability fixes. The proposed method can be integrated with GitHub, enabling automatic vulnerability scanning and fixing during the build process. The research evaluates the effectiveness of the proposed method by demonstrating the ability of the method to improve the security of DevSecOps pipelines. The findings suggest that the proposed method can enhance the overall security of the application by reducing the time to detect and fix vulnerabilities.
Найдено
Ничего не найдено, попробуйте изменить настройки фильтра.
Для доступа к списку цитирований публикации необходимо авторизоваться.
Топ-30
Журналы
|
1
|
|
|
International Journal of Information Security
1 публикация, 5.88%
|
|
|
IEEE Access
1 публикация, 5.88%
|
|
|
EPJ Web of Conferences
1 публикация, 5.88%
|
|
|
Lecture Notes in Networks and Systems
1 публикация, 5.88%
|
|
|
Smart Innovation, Systems and Technologies
1 публикация, 5.88%
|
|
|
AIP Conference Proceedings
1 публикация, 5.88%
|
|
|
1
|
Издатели
|
2
4
6
8
10
12
|
|
|
Institute of Electrical and Electronics Engineers (IEEE)
12 публикаций, 70.59%
|
|
|
Springer Nature
3 публикации, 17.65%
|
|
|
EDP Sciences
1 публикация, 5.88%
|
|
|
AIP Publishing
1 публикация, 5.88%
|
|
|
2
4
6
8
10
12
|
- Мы не учитываем публикации, у которых нет DOI.
- Статистика публикаций обновляется еженедельно.
Вы ученый?
Создайте профиль, чтобы получать персональные рекомендации коллег, конференций и новых статей.
Войти с ORCID
Метрики
17
Всего цитирований:
17
Цитирований c 2025:
10
(58.82%)
Ошибка в публикации?